Chunhua Su

dblp:04/4049 · DBLP profile ↗
← Back
138ranked-venue papers
6as first author
75since 2021 · last 2026
0000-0002-6461-9684ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 53 · 5 first-author · 16 since 2021Computer networks · 33 · 29 since 2021Systems, architecture and hardware · 19 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 16 · 15 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 8 since 2021Databases, data management, data science and information retrieval · 8 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Theory of computation · 2Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 State-disentangled multi-task learning framework for robust photoplethysmography-based biometric authentication on smartwatches
Haitao He, Yifang Huang, Jiadong Ren, Chunhua Su
Expert Syst. Appl.6
2026 DETR-BAL: Decentralized mobile sensing intrusion detection via latent mining and Bayesian local optimization
Chen Zhang 0033, Zhuotao Lian, Huakun Huang, Chunhua Su
Future Gener. Comput. Syst.5
2026 Dynamic Generator: A Stealth-Preserving Generator-Based Data Poisoning Attack in Federated Learning With Defensive Countermeasures in IoT Systems
abstract
Federated Learning (FL) is a distributed learning framework that enables collaborative training of a global model across multiple IoT devices while preserving the privacy of local data. However, this collaborative paradigm also introduces security challenges to the global model. Compromised IoT devices can carry out data poisoning attacks on their local data, uploading malicious model gradients to the cloud server and ultimately degrading the global model performance. Most existing data poisoning methods focus primarily on maximizing attack effectiveness, causing a significant drop in global model accuracy, while often neglecting the stealthiness of the attack. This leads to malicious updates being easily detected and filtered, reducing their threat in IoT deployments. To fill this gap, we propose a stealthy data poisoning method based on a dynamic generator. The approach dynamically generates perturbations with gradient-level stealthiness, achieving a trade-off between poisoning effectiveness and stealthiness in realistic IoT settings. We conducted comprehensive experiments on 3 public IoT datasets: with 30% malicious clients, our attack reduces global accuracy by 10.78% on DeepHealth, 6.07% on ChestMNIST and 7.81% on SVHN, achieving degradation comparable to baselines while preserving stealthiness at the gradient level. To counter this threat, We propose PCATrace, a trajectory-based defense that consistently detects and removes malicious clients across different attack ratios, effectively preventing poisoned updates from degrading the global model.
Xiuheng Liao, Ziang Wu, Buzhen He, Shuai Shang, Di Wu 0050, Chunhua Su
IEEE Internet Things J.7
2026 LRCDA: A Lightweight and Reusable Cross-Domain Authentication Scheme for Industrial IoT Based on Distributed Architecture
abstract
With the continuous expansion of industrial internet of things (IIoT) applications, secure cross-domain authentication has emerged as a critical technical challenge. Traditional authentication schemes based on trusted third parties suffer from single point of failure risks, while blockchain-based decentralized approaches incur excessive computational overhead. Both methods share a common deficiency: authentication nodes must repeatedly execute authentication procedures at each target domain’s gateway when performing cross-domain authentication. This repetitive mechanism significantly increases resource consumption and limits the system’s ability to satisfy strict real-time requirements. To address these challenges, this paper proposes a lightweight and reusable cross-domain authentication scheme (LRCDA) based on distributed architecture. First, the proposed scheme, based on the Chinese Remainder Theorem, enables edge nodes to autonomously establish system keys and independently verify identities, completely eliminating dependence on centralized third parties and mitigating single point of failure risks. Furthermore, the scheme introduces a cross-domain reusable signature mechanism, allowing signature to be securely reused across multiple security domains during its validity period, thereby reducing the frequency of signature generation and minimizing authentication latency. Moreover, through efficient task allocation, computationally intensive operations are offloaded to edge nodes, thereby reducing the computational burden on terminal devices. Theoretical analysis demonstrates that the LRCDA scheme meets the security and privacy requirements for cross-domain authentication in industrial IoT environments, encompassing anonymity, signature unforgeability, and resistance to man-in-the-middle attacks. Experimental evaluations reveal that LRCDA scheme reduces authentication latency by 77.4% compared to traditional schemes and by 88.2% compared to existing distributed approaches, demonstrating significant efficiency gains for resource-constrained industrial IoT deployments.
Tao Feng 0007, Chunhua Su
IEEE Internet Things J.4
2026 Attack-agnostic robust decentralized federated learning
Jiafei Wu, Puning Zhao, Haoyi Yuan, Chunhua Su, Lu Zhou 0002
Knowl. Based Syst.7
2026 Federated continual learning with domain-routed historical expert matching for multimodal perception
Xiuheng Liao, Zhiwei Si, Di Wu 0050, Buzhen He, Chunhua Su
Pattern Recognit.7
2026 CCG-IDS: A Causal Counterfactual Graph-Based Intrusion Detection System for Industrial IoT
abstract
The industrial Internet of Things (IIoT) requires robust intrusion detection systems (IDS) to ensure critical business continuity. However, existing solutions suffer from high false-positive rates, difficulty in interpreting, and cross-domain generalization. In particular, they fail to reliably infer context-dependent causal links from host logs under global graph-level context. To address these issues, we propose causal counterfactual graph-based IDS (CCG-IDS), an IIoT-focused interpretable graph neural network IDS based on conformal calibration and counterfactual reasoning. This system implements a unified provenance subgraph detection paradigm, and employs conformal anomaly detection and counterfactual reasoning to provide calibrated alerts and interpretable outputs. We also estimate predictive uncertainty via Fisher information to quantify decision confidence. We introduce a discrete counterfactual explainer with a counterfactual destructiveness score (CDS) to extract a minimal decision-critical evidence chain, and use this evidence to generate structured analyst-ready security reports. Experiments on real-world industrial log datasets, including the windows event log EVTX (Windows XML Event Log) and DARPA OpTC (Operationally Transparent Cyber) datasets, demonstrated that CCG-IDS achieved an$F1$score of 92% and a near-zero false-positive rate, outperforming other state-of-the-art methods.
Chen Zhang 0033, Huakun Huang, Chunhua Su
IEEE Trans. Ind. Informatics4
2026 ESPL: Efficient and Secure Privacy-Preserving Federated Learning in Internet of Vehicles
Chen Zhang 0033, Tao Feng 0007, Chunhua Su
IEEE Trans. Ind. Informatics4
2025 A Secure and Verifiable Data Sharing Scheme Based on Cloud-Edge Collaboration in the Internet of Vehicles
abstract
With the development of Internet of Vehicles technology, more and more private data from vehicle users are being collected in cloud storage. However, cloud storage adopts a centralized storage model, and once attacked, all the data may be leaked. In addition, to protect data confidentiality, the data owner adopts a ciphertext policy attribute-based encryption scheme to enable one-to-many data sharing and fine-grained access control. The traditional ciphertext-policy attribute-based encryption scheme relies on a single authorization server for managing user attributes and key distribution, making it vulnerable to key misuse attacks and prone to single-point-offailure problem. To resolve these issues, this paper presents a secure and verifiable data sharing scheme leveraging cloud-edge collaboration in the Internet of Vehicles. Data are stored at edge nodes, while metadata are stored at cloud storage to meet users’ low-latency requirements and reduce transmission pressure. In addition, an attribute management and key generation model with multiple authorization servers is proposed to resist key misuse attacks by the attribute authority and to address the single-point-of-failure problem of a single authorization server. Security analysis and experiments demonstrate that the proposed scheme effectively resists various attacks while maintaining low time overhead.
Xiaomei Du, Chunbo Wang, Xiaoqiang Di, Chunhua Su
ISCC5
2025 Assessing the Security of Vibe Coding: Baseline Vs. Security-Oriented Prompts in LLM Code Generation
Runtong He, Huishan Lai, Jingxue Chen, Chunhua Su
ISPEC4
2025 Parallel FHE-Based Neural Network Inference with Knowledge Distillation for Efficient Privacy-Preserving Image Classification
Junyu Lin 0001, Jiageng Chen, Jichao Xiong, Weizhi Meng 0001, Chunhua Su
KSEM (4)6
2025 StressSentry-FHE: A Transformer-Based Privacy-Preserving Framework for Stress Detection Using Quantized Attention
Jichao Xiong, Jiageng Chen, Junyu Lin 0001, Chunhua Su, Weizhi Meng 0001
KSEM (2)5
2025 Prompt-in-Content Attacks: Exploiting Uploaded Inputs to Hijack LLM Behavior
Zhuotao Lian, Qingkui Zeng, Toru Nakanishi 0001, Teruaki Kitasuka, Chunhua Su
NSS6
2025 Federated Intrusion Detection Under Non-IID Traffic
Ziang Wu, Xiuheng Liao, Buzhen He, Shuai Shang, Tianhui Li, Chunhua Su
ProvSec6
2025 PM-SRCANet: A Privacy-Preserving Multimodal Stress Recognition Convolutional Attention Network Model
Jichao Xiong, Wanxuan Wu, Jiageng Chen, Chunhua Su, Weizhong Zhao, Junyu Lin 0001
WASA (3)4
2025 Secure data transmission and classification for digital twin
Weizheng Wang 0001, Dequan Xu, Zhusen Liu, Qipeng Xie, Chunhua Su, Changgen Peng
Sci. China Inf. Sci.5
2025 Privacy-Preserving and Efficient Pneumonia Diseases Detection System Based on Federal Intelligent Edges
abstract
ABSTRACT As pneumonia cases continue to rise worldwide, rapid diagnostic capabilities are essential for effective treatment. However, traditional medical systems often lack efficiency and coordinated management. In response, we propose an AI‐driven biomedical diagnosis platform for real‐time detection and swift intervention. Leveraging privacy‐preserving deep learning on the edge, users can promptly obtain automated diagnoses by uploading chest CT images. To further enhance accuracy, we employ a federated learning (FL) framework that ensures scalable training in an industrial IoT setting while protecting patient data. Our global FL model achieves around 96.25% accuracy on a validation dataset, outperforming individual clients by 3.42%. By eliminating the need for sharing raw data, patient privacy is preserved, and the system offers improved flexibility and scalability for medical diagnosis.
Haoda Wang, Chen Qiu 0007, Chunhua Su
Comput. Intell.4
2025 Efficient unlearning for data security in deep learning systems
abstract
Abstract Machine unlearning in the context of cybersecurity and privacy protection facilitates the removal of specific training data impacts from deep learning (DL) models, adhering to security, privacy, or compliance demands. However, traditional methods can only handle short-term, independent unlearning tasks. Conversely, real-world scenarios often involve extensive unlearning demands from users. Current methods fail to adequately address these demands due to substantial computational overhead and adverse impacts on inference accuracy, leaving the security and privacy of many users at risk. To navigate these challenges adeptly, we introduce the Multi-Agent Reinforcement Learning Data Lifecycle Management (MADLM) strategy. MADLM intricately examines the interactions between unlearning and continuous learning processes, enabling the postponement of certain tasks for combined execution to optimize computational resources. Concurrently, it employs strategic data management to maintain and enhance inference accuracy. Furthermore, by utilizing Multi-Agent Reinforcement Learning (MARL), MADLM dynamically orchestrates task scheduling to minimize computational demands, improve task response times, and bolster inference reliability, crucial for upholding stringent cybersecurity and privacy standards. Our evaluations of MADLM reveal substantial enhancements, including a 6% uplift in inference accuracy and a dramatic reduction in computational overhead to merely 12% of the original demands, effectively expanding the data security protections.
Enting Guo, Chunhua Su, Peng Li 0017
Comput. J.2
2025 A privacy-enhancing and lightweight framework for device-free localization-based AIoT system
Haoda Wang, Chen Zhang 0033, Lingjun Zhao, Huakun Huang, Chunhua Su
Comput. Commun.5
2025 Adversarial Robustness Encoder as a Service for Classifiers on Internet of Things Devices
abstract
Within the Internet of Things (IoT) landscape, Encoder as a Service (EaaS) is a cloud-based service for many AI empowered scenarios, such as autopilot and face-scan payment, enabling IoT devices to keep a light classifier model at local while remotely accessing powerful encoding models. However, adversarial examples like an image with imperceptible tiny perturbations that can lead to incorrect classifying results, make it challenging to achieve a robust EaaS-based classifier. Certified radius (R) emerges as a measure against such imperceptible tiny perturbations, and guarantees the trustworthiness of any input with perturbations smaller than R. Despite offering R related services, the substantial computational overhead from traditional methods, stemming from the extensive searches of R for each request, poses a barrier to their practical deployment. In this article, we identify the repetitive computations in the EaaS framework due to the fixed encoding model and propose a novel search cache scheme to speed up the R-related computation. Therefore, we propose large-scale efficient robust EaaS (ScaleRES) to address different R-related services: First, ScaleRES strategically stores previous computation results of R, to enable the reuse and refining of R across users. Then, ScaleRES obtains the average certified radius (ACR) efficiently with selective cached R. Finally, ScaleRES performs R filtering to enhance adversarial training for a robust EaaS-based classifier. Comprehensive evaluations demonstrate that in three distinct computations, ScaleRES offers significant savings in computational overhead compared to the conventional approach—70% for R computation as the number of clients increases, 35% for ACR of the entire test set, and 40% for adversarial training with robustness comparable to other works.
Enting Guo, Shengli Pan 0001, Chunhua Su, Peng Li 0017
IEEE Internet Things J.4
2025 CD-BISHAC: Cross-Domain Scheme for Blockchain-Based Industrial Internet of Things Security Hybrid Access Control
abstract
The Industrial Internet of Things (IIoT) is currently confronted with significant security challenges, including the complexities associated with cross-domain device permission management, the risks of privacy breaches during data transmission, and the vulnerabilities inherent in centralized security architectures to various forms of attack. Existing access control schemes are inadequate for addressing the dynamic and intricate nature of industrial environments, often falling short of meeting the IIoT system’s flexibility, security, and scalability requirements. This article introduces a novel hybrid access control scheme based on blockchain technology within a cross-domain context to tackle these issues. This approach synergizes the simplicity of role-based access control (RBAC) with the adaptability offered by attribute-based access control (ABAC) while harnessing blockchain’s decentralization, immutability, and transparency to bolster system security, autonomy, and capabilities for cross-domain management. We assessed this scheme’s effectiveness in defending against various threats through comprehensive security analysis. Furthermore, experimental results indicate that our proposed solution provides robust security guarantees and surpasses traditional approaches regarding efficiency and performance. Consequently, the scheme presented herein signifies a substantial innovation in IIoT security practices—offering a feasible and reliable solution tailored for complex cross-domain environments.
Buzhen He, Tao Feng 0007, Chunhua Su
IEEE Internet Things J.4
2025 Privacy-Enhanced Federated WiFi Sensing for Health Monitoring in Internet of Things
abstract
The development of the Internet of Things (IoT) has led to the widespread use of WiFi-enabled consumer electronic devices, which are now common in everyday life. These advancements in IoT have greatly improved data collection and analysis capabilities, especially for health monitoring applications. However, traditional centralized machine learning methods often fall short, raising significant privacy concerns and requiring extensive data collection, which is inefficient. To address these limitations within the distributed IoT environment, this article presents a federated learning (FL)-based WiFi sensing system specifically designed for health monitoring. By enabling local model training, our system prevents the sharing of sensitive data, thus reducing the risk of privacy breaches. We further enhance our system with a secret sharing mechanism coupled with model sparsification to significantly improve privacy. Additionally, our improved top-k model sparsification algorithm, equipped with adaptive residuals, reduces communication overhead while ensuring high accuracy. Extensive testing across various datasets and models confirms that our system outperforms existing benchmarks in terms of privacy protection and communication efficiency, marking a substantial advancement in health monitoring within the IoT.
Zhuotao Lian, Qingkui Zeng, Zhusen Liu, Haoda Wang, Chuan Ma 0001, Weizhi Meng 0001, Chunhua Su, Kouichi Sakurai
IEEE Internet Things J.7
2025 RTCS: An Improved Real-Time Credibility-Based Intrusion Detection System
abstract
The Internet of Things (IoT) connects physical devices to the Internet via open communication protocols. Malicious actors can exploit vulnerabilities to steal data or manipulate critical IoT settings, so there is a need for strong security measures. We propose an improved real-time intrusion detection system (IDS) called the real-time credibility system (RTCS), which utilizes traffic statistics and authentication analysis to compute credibility. RTCS performs the authentication process by utilizing elliptic curve encryption and decryption operations, basic symmetric encryption, and hash functions. This process enables anonymous mutual authentication between IoT devices. Subsequently, RTCS accesses sparsified user history data and introduces flexibility in calculating user credibility by employing an adapted secondary paradigm combined with preset “tolerance parameters,” which serve as optimal thresholds for classifying different users. When a normal user violates regulations, their credibility decreases by a specified degree. If a high-risk user commits another violation, RTCS cannot tolerate it, leading to a rapid decline in their credibility. RTCS implements diversion measures and provides assisted decision scores for different users. Experimental results demonstrate that our method achieves an F1-score of 0.9707 and an area under the curve score of 0.9535. Compared to other works, RTCS exhibits superior performance and proactivity.
Chen Zhang 0033, Zhuotao Lian, Huakun Huang, Chunhua Su
IEEE Internet Things J.4
2025 BARM: Blockchain-Assisted Anonymous Authentication and Reputation Management for Mobile Crowdsensing in Internet of Vehicles
abstract
Mobile crowdsensing (MCS) utilizes sensors distributed across different vehicles to support intelligent transportation and environmental monitoring. Recently, most of the research on MCS in Internet of Vehicles (IoV) mainly focuses on privacy protection and data security of anonymous authentication, but there are still shortcomings in reliability evaluation and reputation management of sensing vehicles. Besides, the lack of effective management of identity information may lead to difficulties in tracking malicious behavior. In this article, we propose a blockchain-assisted anonymous authentication and reputation management (BARM) scheme for MCS in IoV. Specifically, an efficient anonymous authentication algorithm is proposed for sensing vehicles. Then, the privacy protection reputation evaluation algorithm is proposed to ensure the reliability of the sensing vehicles and the security of sensing data. Meanwhile, an accurate reputation update algorithm is proposed to effectively check and update the reputation values of participating sensing vehicles. Besides, the smart contracts are written and deployed on the blockchain to manage the information of the sensing vehicles, which improves the security, efficiency, and trust of the identity management. Subsequently, a formal security verification method based on colored petri net (CPN) and Dolev-Yao attacker model is proposed to evaluate the security of the scheme. The evaluation results show that the scheme can effectively resist a variety of different types of attacks and has multiple security attributes. Performance analysis shows that the proposed scheme has low computation and communication overheads and high robustness.
Tao Feng 0007, Zilong Xie, Chunhua Su
IEEE Internet Things J.5
2025 MSAUPL: A multi-server authentication and key agreement protocol for industrial IoT based on user privacy level
Tao Feng 0007, Chunhua Su
J. Inf. Secur. Appl.3
2025 Attack Analysis and Enhanced Authentication Protocol Design for Vehicle Networks
abstract
Vehicular Ad-hoc Networks (VANETs) face significant security and privacy challenges in modern intelligent transportation systems. This paper analyzes vulnerabilities in Al-Shareeda et al.'s vehicle authentication protocol (doi: 10.1109/TDSC.2025.3553868) and proposes an enhanced ECC-based scheme using short-lived pseudonymous certificates. We identify two critical weaknesses in Al-Shareeda et al.'s protocol—a desynchronization attack causing potential denial-of-service and an identity linking attack compromising vehicle privacy. Our protocol establishes mutual authentication between vehicles and roadside units, ensuring message integrity, anonymity, and perfect forward secrecy. Unlike existing approaches, it eliminates the need for online third-party authenticators. Formal security proofs demonstrate that the scheme's security is reducible to the hardness of the ECDLP and CDH problems. Performance analysis shows our approach achieves an optimal security-efficiency balance with competitive communication overhead (4608 bits) and computation costs (5.02 ms) compared to state-of-the-art alternatives, while uniquely satisfying all twelve evaluated security properties.
Weizheng Wang 0001, Qipeng Xie, Yongzhi Huang 0002, Yong Ding 0005, Lejun Zhang, Demin Gao, Chunhua Su, Joel J. P. C. Rodrigues
IEEE Trans. Dependable Secur. Comput.7
2025 Enhanced V2R Authentication for VANETs Using Group Signatures and Dynamic Pseudonyms
abstract
Vehicular Ad Hoc Networks (VANETs) facilitate real-time information exchange through Vehicle-to-Vehicle (V2V) and Vehicle-to-Roadside (V2R) communications. While V2R communication plays a crucial role, it faces significant security challenges due to the transmission of sensitive data, leaving the system vulnerable to man-in-the-middle, replay, and impersonation attacks. Previous attempts to enhance security, such as dynamic anonymization and trusted key management, have introduced new challenges, including complex authentication processes, high resource demands, and inadequate privacy protection. To overcome these issues, we propose a lightweight and efficient authentication scheme that enhances vehicle privacy and security through a combination of signatures, pseudonyms, batch verification, and flexible certificate management. Our approach also employs Bloom filters to improve authentication efficiency, addressing the limitations of traditional certificate management systems that suffer from large lists and slow query times. The evaluation results demonstrate that the proposed scheme ensures comprehensive security by providing two-way authentication and guaranteeing anonymity. It effectively prevents replay attacks, DoS attacks, and other potential threats. Moreover, the scheme significantly reduces both communication and computational overhead, offering an efficient and secure solution for V2R communication in VANET.
G. Thippa Reddy, Weizheng Wang 0001, Chunhua Su
IEEE Trans. Intell. Transp. Syst.6
2025 Secure Enhanced IoT-WLAN Authentication Protocol With Efficient Fast Reconnection
abstract
The increasing integration of Internet of Things (IoT) devices in Wireless Local Area Networks (WLANs) necessitates robust and efficient authentication mechanisms. While existing IoT authentication protocols address certain security concerns, they often fail to provide comprehensive protection against threats such as perfect forward secrecy violations, insider attacks, and key compromise impersonation, or impose significant computational and communication overhead on resource-constrained IoT systems. This paper presents a novel Extensible Authentication Protocol (EAP) based scheme for IoT-WLAN environments that addresses these security challenges while maintaining cost-effectiveness. Our approach utilizes elliptic curve cryptography and incorporates advanced features including perfect forward secrecy, strong identity protection, and explicit key confirmation. We provide a thorough security analysis using informal heuristics, formal methods (Random Oracle Model and BAN Logic), and automated verification with ProVerif. Performance evaluations demonstrate that our protocol achieves lower communication, storage, and computational costs compared to state-of-the-art solutions, with an average 79.6% reduction in computation time. A detailed comparison with existing schemes highlights the efficiency and enhanced security features of our proposed authentication mechanism for IoT-WLAN deployments.
Weizheng Wang 0001, Qipeng Xie, Chunhua Su, Joel J. P. C. Rodrigues, Kaishun Wu
IEEE Trans. Mob. Comput.4
2024 Dynamic Channel Key Regeneration Scheme with LFSR for Secure IoT Communications
abstract
Securing the communication of wireless devices within the Internet of Things (IoT) ecosystem is a critical concern that garners considerable attention. Nowadays, leveraging physical layer data to generate lightweight channel keys for wireless devices has become a prevalent approach. However, most existing methodologies focus primarily on the key establishment for singular communication instances, often neglecting the intricate needs for ongoing key generation and renewal throughout multiple communication sessions. This paper introduces a novel channel key regeneration scheme that leverages previously utilized information from successful channel key generations. To enhance the randomness and security of the renewed key, the proposed design incorporates a linear feedback shift register (LFSR) for the generation and adjustment of new channel keys. This method aims to establish a more dynamic and secure channel key management framework, catering to the evolving demands of IoT communications.
Enting Guo, Chunhua Su, Xinyi Huang 0001
GLOBECOM3
2024 Reentrancy vulnerability detection based on graph convolutional networks and expert patterns under subspace mapping
Longtao Guo, Huakun Huang, Lingjun Zhao, Peiliang Wang, Shan Jiang 0005, Chunhua Su
Comput. Secur.6
2024 Traffic Sign Recognition Using Optimized Federated Learning in Internet of Vehicles
abstract
Traffic sign recognition (TSR) is vital for vehicle safety and navigation, especially in the era of autonomous cars. Internet of Vehicles (IoV) provide a promising infrastructure for vehicular networks due to their agility and interoperability. However, privacy concerns and network restrictions hinder the collection of massive data from distributed automotive sensors in IoV. To address these challenges, this article proposes the application of federated learning (FL) and model sparsification to optimize traffic sign recognition (TSR) in autonomous vehicles. FL enables decentralized learning while preserving data privacy, and model sparsification significantly reduces communication costs. Furthermore, we incorporate the Adam optimizer for local training, ensuring efficient model optimization on each vehicle. Experimental results demonstrate the effectiveness of our approach, with improved TSR performance while mitigating privacy risks and enhancing communication efficiency. This research contributes to the advancement of TSR in IoV by introducing FL, model sparsification, and the use of the Adam optimizer for local training, facilitating efficient and privacy-preserving vehicular network learning.
Zhuotao Lian, Qingkui Zeng, Weizheng Wang 0001, Dequan Xu, Weizhi Meng 0001, Chunhua Su
IEEE Internet Things J.6
2024 Lightweight Blockchain-Enhanced Mutual Authentication Protocol for UAVs
abstract
With the rapid increase of data from unmanned aerial vehicles (UAVs), the security and privacy of data presents a severe challenge for UAV-based applications. Moreover, UAVs with constrained resources cannot be equipped with strong but complicated cryptographic primitives for authentication protocol design. Although some attempts have been made to deal with security and privacy issues for UAVs, most of the existing studies have been found numerous security vulnerabilities or own extreme communication/computation overheads. This article offers a lightweight and practical mutual authentication protocol solely comprised of bitwise XOR operations and one-way hash functions. Moreover, blockchain technology is utilized to alleviate the centralized trusted party (TA) issue. Then, security of our proposed authentication protocol is proved by widely adopted formal security proof—Real-or-Random model and informal security proof. The experimental results prove that the proposed protocol can achieve better security requirements (e.g., decentralized TA, replay attack defense, and session key security) with less communication cost (i.e., reduced by around 58.7% at most) and computation cost (i.e., reduced by around 98.9% at most) than related UAV authentication schemes.
Weizheng Wang 0001, G. Thippa Reddy, Saleem Raza, Jawad Tanveer, Chunhua Su
IEEE Internet Things J.6
2024 PCIDS: Permission and Credibility-Based Intrusion Detection System in IoT Gateways
abstract
The Internet of Things (IoT) has evolved into a global platform dramatically facilitating human life through intelligent services. It is straightforward for people to access smart devices through IoT. However, the easy accessibility of IoT devices has also led to unprecedented security challenges for the IoT. To ensure the security of the basic structure of IoT, we need to establish a security barrier that can filter malicious access to IoT devices and achieve the integration of intrusion detection systems (IDSs) with intelligent gateways. This article establishes threat models of Denial of Service, Replay, man-in-the-middle, and Loophole attacks based on statistical flow characteristics and identity authentication. It uses supervised learning to obtain the credibility index to protect the IoT system. We use the Django framework to verify identity authorization information, the decision tree to determine request attributes, and the real-time status feedback from IoT devices to perform a risk assessment on the current user by precalculating the importance ratio (Ir), the maximum credibility index$(P_{\mathrm {max}})$, and the minimum credibility index$(P_{\mathrm {min}})$. With administrator verification, we conduct a convergence analysis to obtain user attributes. The experimental results show that our approach achieves a recognition accuracy of 94.7%.
Chen Zhang 0033, Zhuotao Lian, Huakun Huang, Chunhua Su
IEEE Internet Things J.4
2024 A review and implementation of physical layer channel key generation in the Internet of Things
abstract
Physical layer channel key generation is a promising technology for secure communication in wireless network security , which mainly establishes secure communication keys between any two legitimate users. This article reviews current techniques for physical layer channel key generation. The physical layer channel key generation principle, system model, attack model, key generation process, and experimental application are comprehensively reviewed. In addition, we introduce the experimental scenarios of key generation and the collection methods of channel measurements in wireless applications and simulation platforms and summarize the experimental equipment configuration and actual operation in the process of collecting different measurements. The article concludes with some suggestions for future research.
Enting Guo, Zhuotao Lian, Xinyi Huang 0001, Chunhua Su
J. Inf. Secur. Appl.6
2024 I-Health: SDN-Based Fog Architecture for IIoT Applications in Healthcare
abstract
The Industrial Internet of Things (IIoT) has been introduced in an era of increasingly broad potentials in the medical industry. In recent years, IIoT-based healthcare applications have grown in popularity, with the majority of them relying on Wireless Body Area Network (WBAN) for flexibility. There have been a few recent works that have investigated SDN-based fog architecture for constructing smart healthcare systems. However, the best fog node from the fog layer must be identified and limit the transmission of unnecessary data. To address this issue, the Intelligent Software-defined Fog Architecture (i-Health) is developed in this work. Based on the prior data pattern of each patient, the controller will decide whether to send the data to the fog layer. Furthermore, we introduced the Fog Ranking Service (FRS) and Fog Probing Service (FPS) to select the best fog node. The performance comparison reveals that the proposed i-Health outperforms existing benchmark approaches.
Joy Lal Sarkar, V. Ramasamy, Abhishek Majumder, Bibudhendu Pati, Chhabi Rani Panigrahi, Weizheng Wang 0001, Nawab Muhammad Faseeh Qureshi, Chunhua Su, Kapal Dev
IEEE Trans. Comput. Biol. Bioinform.8
2024 FIND: Privacy-Enhanced Federated Learning for Intelligent Fake News Detection
abstract
The development and popularity of social networks have made information dissemination unprecedentedly convenient and speedy. However, the spread of fake news can often cause serious harm to society and individuals. Therefore, machine learning-based fake news detection methods have become increasingly important. The existing work often needs to collect sufficient user-side data for training, which also boosts the privacy leakage risk to the users. Therefore, this article proposes an intelligent fake news detection system based on federated learning (FL) called FIND, which can train a global model while keeping user data locally. At the same time, we also designed a sparsified update perturbation method to enhance the system security further. Finally, we conduct simulation experiments to study and discuss multiple acoustic factors and prove the feasibility of our system in terms of accuracy, security, and efficiency.
Zhuotao Lian, Chen Zhang 0033, Chunhua Su, Fayaz Ali Dharejo, Mutiq Almutiq, Muhammad Hammad Memon
IEEE Trans. Comput. Soc. Syst.3
2024 DeFiScanner: Spotting DeFi Attacks Exploiting Logic Vulnerabilities on Blockchain
abstract
With the rapid development of decentralized financial (DeFi), the total value locked (TVL) in DeFi continues to increase. A big number of adversaries exploit logic vulnerabilities to attack DeFi applications for profit, such as flash loan attacks and price manipulation attacks. However, the current vulnerability detection tools for smart contracts cannot be directly used to detect the logic vulnerabilities generated by the combination of different protocols. How to characterize and detect DeFi attacks that exploited logic vulnerabilities is a big challenge. In this work, we propose a deep-learning-based attack detection system on DeFi, called DeFiScanner, in which we design a novel neural network that includes a global model, a local model, and a fusion model to characterize DeFi attacks. First, the unstructured emitted events are automatically and efficiently normalized. Second, the transaction-related features of normalized emitted events are enriched with the global model and the semantic features of emitted events are extracted with the local model. Finally, the transaction-related features and the semantic features of emitted events are fused efficiently with the fusion model to detect DeFi attacks. We collect a dataset that consists of 50 910 real-world DeFi transactions on Ethereum (ETH). The extensive experimental results demonstrate the effectiveness of DeFiScanner. The true positive rate (TPR) and the area under the receiver operating characteristic (ROC) curve of the system reach 0.91 and 0.97, respectively.
Bin Wang 0051, Hongliang Ma, Bin Wang 0062, Chunhua Su, Wei Wang 0012
IEEE Trans. Comput. Soc. Syst.6
2024 LDS-FL: Loss Differential Strategy Based Federated Learning for Privacy Preserving
abstract
Federated Learning (FL) has attracted extraordinary attention from the industry and academia due to its advantages in privacy protection and collaboratively training on isolated datasets. Since machine learning algorithms usually try to find an optimal hypothesis to fit the training data, attackers also can exploit the shared models and reversely analyze users’ private information. However, there is still no good solution to solve the privacy-accuracy trade-off, by making information leakage more difficult and meanwhile can guarantee the convergence of learning. In this work, we propose a Loss Differential Strategy (LDS) for parameter replacement in FL. The key idea of our strategy is to maintain the performance of the Private Model to be preserved through parameter replacement with multi-user participation, while the efficiency of privacy attacks on the model can be significantly reduced. To evaluate the proposed method, we have conducted comprehensive experiments on four typical machine learning datasets to defend against membership inference attack. For example, the accuracy on MNIST is near 99%, while it can reduce the accuracy of attack by 10.1% compared with FedAvg. Compared with other traditional privacy protection mechanisms, our method also outperforms them in terms of accuracy and privacy preserving.
Taiyu Wang, Qinglin Yang, Kaiming Zhu, Junbo Wang 0001, Chunhua Su, Kento Sato
IEEE Trans. Inf. Forensics Secur.5
2024 Privacy-Preserving Distributed Transfer Learning and Its Application in Intelligent Transportation
abstract
With the rapid development of intelligent transportation systems (ITS), more and more intelligent applications for ITS have received widespread attention, such as the vehicle detection, inference of typical routes, and traffic forecasting. In these applications, deep learning is widely used as a key artificial intelligence technology. However, most ITS providers fail to collect enough labeled traffic data for model training. As a complement to deep learning, transfer learning is an effective way to solve the scarcity of labeled data, which can transfer knowledge from labeled datasets to unlabeled datasets, thus improving the accuracy of prediction and classification. Nevertheless, when the labeled dataset and the unlabeled dataset are held by different entities, it is still unrealistic for two mutually distrustful entities to cooperate in transfer learning regarding data security and privacy preservation. Although some existing works provide privacy-preserving transfer learning methods, such methods fail to apply to traffic data with high sample dimensions due to their high computational cost and round complexity. To address this problem, we design an efficient privacy-preserving distributed transfer learning protocol, which is appropriate for traffic data. Compared to existing works, our protocol addresses the privacy-preserving problem of transfer learning for traffic data with high sample dimensions. In addition, our protocol has fewer interaction rounds and can be proved in the semi-honest model. Finally, we validate the effectiveness, efficiency and security of the proposed protocol via experiments. Furthermore, we show the application of the proposed protocol in intelligent transportation systems.
Zhi Li 0056, Hao Wang 0007, Guangquan Xu, Alireza Jolfaei, James Xi Zheng, Chunhua Su, Wenying Zhang 0001
IEEE Trans. Intell. Transp. Syst.6
2024 Neighbor-Enhanced Representation Learning for Link Prediction in Dynamic Heterogeneous Attributed Networks
abstract
Dynamic link prediction aims to predict future connections among unconnected nodes in a network. It can be applied for friend recommendations, link completion, and other tasks. Network representation learning algorithms have demonstrated considerable effectiveness in various prediction tasks. However, most network representation learning algorithms are based on homogeneous networks and static networks for link prediction that do not consider rich semantic and dynamic information. Additionally, existing dynamic network representation learning methods neglect the neighborhood interaction structure of the node. In this work, we design a neighbor-enhanced dynamic heterogeneous attributed network embedding method (NeiDyHNE) for link prediction. In light of the impressive achievements of the heuristic methods, we learn the information of common neighbors and neighbors’ interaction in heterogeneous networks to preserve the neighbors proximity and common neighbors proximity. NeiDyHNE encodes the attributes and neighborhood structure of nodes as well as the evolutionary features of the dynamic network. More specifically, NeiDyHNE consists of the hierarchical structure attention module and the convolutional temporal attention module. The hierarchical structure attention module captures the rich features and semantic structure of nodes. The convolutional temporal attention module captures the evolutionary features of the network over time in dynamic heterogeneous networks. We evaluate our method and various baseline methods on the dynamic link prediction task. Experimental results demonstrate that our method is superior to baseline methods in terms of accuracy.
Wei Wang 0012, Chongsheng Zhang, Weiping Ding 0001, Bin Wang 0062, Yaguan Qian, Zhen Han 0001, Chunhua Su
ACM Trans. Knowl. Discov. Data8
2024 Comments on "EAKE-WC: Efficient and Anonymous Authenticated Key Exchange Scheme for Wearable Computing"
abstract
In the above paper, Tu et al. proposed an efficient and anonymous authenticated key exchange scheme optimized for wearable computing environments, utilizing lightweight cryptographic primitives like XOR, ASCON, and hash functions. They claimed the employed Authenticated Key Exchange (AKE) scheme is robust against prevalent security threats. However, our analysis reveal a critical vulnerability to replay attacks that could undermine the protocol's security; specifically, an attacker could intercept messages and induce unauthorized server-side password updates, effectively blocking further legitimate user communications. Upon dissecting the root causes of this vulnerability, we offer targeted recommendations to mitigate such attacks and reinforce the protocol's defenses.
Weizheng Wang 0001, Chunhua Su
IEEE Trans. Mob. Comput.3
2023 Instant and Secure Channel Key Extraction Scheme Among Wireless Devices
abstract
Device-to-device communication is increasingly important for emerging wireless applications, including the Internet of Things and industry mobile networks. To establish a secure communication channel between multiple legitimate devices, key agreement is an essential first step. Physical layer channel information is a promising technology for achieving communication security by generating a shared channel key. In this paper, we propose an efficient and random method for generating channel keys based on channel state information (CSI). Firstly, we preprocess the available subcarriers to reduce the correlation of adjacent subcarriers. Secondly, we propose a novel quantization process to generate random and secure channel keys. The part consists of two phases: the quantization phase and the inconsistency removal phase. In the quantization stage, CSI sub carriers are grouped into small blocks, and appropriate thresholds are generated. Then, wireless users quantize the CSI subcarriers into initial bit streams of 0 and 1 with different thresholds. In the inconsistency removal phase, we design an error correction mechanism where wireless users exchange the discarded index sequences in the initial bit streams to achieve key sequence consistency. We implement the proposed scheme using off-the-shelf wireless devices and evaluate its performance. The experimental results show that each CSI packet can produce 30 bits, which have passed the NIST randomness tests.
Enting Guo, Chunhua Su, Xinyi Huang 0001
GLOBECOM3
2023 Efficient and Appropriate Key Generation Scheme in Different IoT Scenarios
Enting Guo, Chunhua Su, Xinyi Huang 0001
ICICS3
2023 BrokerFi: A DeFi dApp Built upon Broker-based Blockchain
abstract
A number of promising blockchain scalability technologies such as Rollups, facilitate the fast and cost-effective asset transfer by offloading transactions from a mainchain to sidechains. The proposed broker-based decentralized application (dApp) in this paper, named BrokerFi, also employs a sidechain approach that works as a Layer2 solution on top of a Layer1 blockchain. Comparing with conventional sidechain solutions, the distinct feature of BrokerFi is that the sidechain used in BrokerFi is a sharded blockchain, in which users can stably earn money without economic risks when they stake money to BrokerFi.BrokerFi is designed as a dApp that can offer functionalities to enable users to manage their digital assets and earn money if they join BrokerFi’s ecology. Users can change the native tokens issued by BrokerFi using their fiat money. Users can also choose to stake their money in the protocol of BrokerFi and earn profit. We mainly demonstrate the design of BrokerFi in this paper. The significant components of BrokerFi mainly include two parts, i.e., the frontend used by users, and the backend that provides fundamental functionalities for BrokerFi in a Layer2-like sidechain. Experiment results show that the proposed BrokerFi can help clients earn high revenue when their staked tokens follow a low variance.
Qinde Chen, Chunhua Su, Huawei Huang
ICPADS3
2023 Mining for Better: An Energy-Recycling Consensus Algorithm to Enhance Stability with Deep Learning
Zhen Xia, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
ISPEC9
2023 SPoiL: Sybil-Based Untargeted Data Poisoning Attacks in Federated Learning
Zhuotao Lian, Chen Zhang 0033, Kaixi Nan, Chunhua Su
NSS4
2023 MMDSSE: Multi-client and Multi-keyword Dynamic Searchable Symmetric Encryption for Cloud Storage
abstract
Since data outsourcing poses privacy concerns with data leakage, searchable symmetric encryption (SSE) has emerged as a powerful solution that enables clients to perform query operations on encrypted data while preserving their privacy. Dynamic SSE schemes have been proposed to handle update operations. However, it is shown that updates might increase the risk of information leakage. Meanwhile, to meet the requirement of real-world applications, it is desirable to have the searchable encryption scheme which supports both multiple clients and multi-keyword queries. To address these issues, this paper proposes MMDSSE, a multi-client forward secure dynamic SSE scheme that supports multi-keyword queries. MMDSSE allows the clients narrow down the results by providing an arbitrary subset of the entire archive, and thus suitable for cloud storage environment. Security analysis and experimental evaluations show that MMDSSE is secure and efficient.
Panyu Wu, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
PST10
2023 MDPPC: Efficient Scalable Multiparty Delegated PSI and PSI Cardinality
abstract
Private Set Intersection (PSI) is one of the most important functions in secure multiparty computation (MPC). PSI protocols have been a practical cryptographic primitive and there are many privacy-preserving applications based on PSI protocols such as computing conversion of advertising and distributed computation. Private Set Intersection Cardinality (PSI-CA) is a useful variant of PSI protocol. PSI and PSI-CA allow several parties, each holding a private set, to jointly compute the intersection and cardinality, respectively without leaking any additional information. Nowadays, most PSI protocols mainly focus on two-party settings, while in multiparty settings, parties are able to share more valuable information and thus more desirable. On the other hand, with the advent of cloud computing, delegating computation to an untrusted server becomes an interesting problem. However, most existing delegated PSI protocols are unable to efficiently scale to multiple clients. In order to solve these problems, this paper proposes MDPPC, an efficient PSI protocol which supports scalable multiparty delegated PSI and PSI-CA operations. Security analysis shows that MDPPC is secure against semi-honest adversaries and it allows any number of colluding clients. For 15 parties with set size of 220on server side and 216on clients side, MDPPC costs only 81 seconds in PSI and 80 seconds in PSI-CA, respectively. The experimental results show that MDPPC has high scalability.
Xiaolei Dong, Zhenfu Cao, Yunbo Yang, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su, Zongyang Hou
PST10
2023 A coordinates-based hierarchical computing framework towards spatial data processing
Chen Qiu 0007, Haoda Wang, Qinglin Yang, Chunhua Su, Huawei Huang
Comput. Commun.4
2023 A Lightweight Blockchain-Based Remote Mutual Authentication for AI-Empowered IoT Sustainable Computing Systems
abstract
Internet of Things (IoT) has led to significant advancements in communication technologies, specifically, concerning IoT-based sustainable information systems. Lately, industry-academic communities have made great strides for the development of security in IoT-based applications, such as traffic management, industrial automation systems, military surveillance systems, transportation, parking, etc. The sustainable IoT converges AI and blockchain technologies for enhancing quality of individual’s life. As a result, emerging IoT applications operate a distributed ledger technology to provide robust-level of encryption and execution for contractual agreement that resolves interoperability and security issues. Thus, this article proposes a blockchain-based remote mutual authentication (B-RMA) that considers smart devices and cloud networks to offer security and privacy. The proposed B-RMA can coexist with the IoT-based smart environment to decentralize the processing of user authentication requests. The prominence of the proposed strategies including security efficiency and privacy protection, is evaluated using informal security analysis. Moreover, a runtime platform “Node.js” was used to analyze the communication metrics, such as execution time, throughput, and overhead ratio, over the concurrent requests. The investigation results prove that the B-RMA achieves a scalable environment, accordingly.
Bakkiam David Deebak, Fida Hussain Memon, Sunder Ali Khowaja, Kapal Dev, Weizheng Wang 0001, Nawab Muhammad Faseeh Qureshi, Chunhua Su
IEEE Internet Things J.7
2023 Blockchain-Based Two-Stage Federated Learning With Non-IID Data in IoMT System
abstract
The Internet of Medical Things (IoMT) has a bright future with the development of smart mobile devices. Information technology is also leading changes in the healthcare industry. IoMT devices can detect patient signs and provide treatment guidance and even instant diagnoses through technologies, such as artificial intelligence (AI) and wireless communication. However, conventional centralized machine learning approaches are often difficult to apply within IoMT devices because of the difficulty of large-scale collection of patient data and the potential risk of privacy breaches. Therefore, we propose a blockchain-based two-stage federated learning approach that allows IoMT devices to train a global model collaboratively without gathering the data to a central server. Specifically, to address the problem of poor training performance on non-independent identically distributed (non-IID) data, we design a blockchain-based data-sharing scheme that can significantly improve the model’s accuracy without threatening user privacy. We also design a client selection mechanism to further improve the system’s efficiency. Finally, we validate the feasibility and effectiveness of our system through simulation experiments on three popular datasets (i.e., MNIST, Fashion-MNIST, and CIFAR-10).
Zhuotao Lian, Qingkui Zeng, Weizheng Wang 0001, G. Thippa Reddy, Chunhua Su
IEEE Trans. Comput. Soc. Syst.5
2023 RSSI Map-Based Trajectory Design for UGV Against Malicious Radio Source: A Reinforcement Learning Approach
abstract
Trajectory design is of great significance for the intelligent Unmanned Ground Vehicle (UGV) when performing various ground tasks. Though obstacle avoidance, speed control and other movement issues in the UGV navigation have been considered by the current research, the UGV path planning against malicious radio source is off the beaten path. To address such a research gap, we propose a reinforcement learning-based scheme to design UGV trajectory against malicious radio source as well as minimize the movement cost. Firstly, the malicious radio source detection and localization models are introduced after the Received Signal Strength Indicator (RSSI) map establishment. Then, the RSSI Map-based UGV trajectory design problem is formulated, where the movement cost and security risk are both concerned. To solve the formed problem, we propose a reinforcement learning-based trajectory design scheme, whose complexities are analyzed in detail. Finally, experiments are conducted under various parameter settings, where the simulation results evaluate the correctness and effectiveness of the proposed algorithm.
Yaoqi Yang, Weizheng Wang 0001, Lu Zhou 0002, G. Thippa Reddy, Mamoun Alazab, Prosanta Gope, Chunhua Su
IEEE Trans. Intell. Transp. Syst.8
2023 Loss-based differentiation strategy for privacy preserving of social robots
Qinglin Yang, Taiyu Wang, Kaiming Zhu, Junbo Wang 0001, Yu Han 0013, Chunhua Su
J. Supercomput.6
2023 Correction to: Loss-based differentiation strategy for privacy preserving of social robots
Qinglin Yang, Taiyu Wang, Kaiming Zhu, Junbo Wang 0001, Yu Han 0013, Chunhua Su
J. Supercomput.6
2023 Blockchain-Based Personalized Federated Learning for Internet of Medical Things
abstract
The rapid growth of artificial intelligence (AI), blockchain technology, and edge computing services have enabled the Internet of Medical Things (IoMT) to provide various healthcare services to patients, including neural network-based disease diagnosis, heart rate monitoring, and fall detection. Generally, end devices should transmit the collected patient data to a centralized server for further model training, but at the same time, the patient's privacy may be at risk. In addition, due to the diversity of patient conditions, a one-size-fits-all model cannot meet personalized healthcare needs. To address the above challenges, we propose a blockchain-based personalized federated learning (FL) system that enables clients to participate in personalized model training without directly uploading private data. We further realize the decentralized FL by combining blockchain technology, which improves the security level of the system. Finally, we verify the reliable performance of our system on different datasets through simulation experiments.
Zhuotao Lian, Weizheng Wang 0001, Chunhua Su
IEEE Trans. Sustain. Comput.4
2022 Decentralized Federated Learning for Internet of Things Anomaly Detection
abstract
With the improvement of computing power and the development of network technology, Internet of Things (IoT) devices are widely used in many industries. But it also faces various security threats. Anomaly detection is a commonly used method, but traditional methods face shortcomings such as low accuracy. Therefore, in this paper, we introduce a decentralized federated learning method for anomaly detection, using neural networks to improve accuracy and take advantage of the characteristics of federated learning to protect local data security. The decentralized algorithm avoids the drawbacks of traditional federated learning such as the single point of failure. Finally, we conduct simulation experiments on the IoT23 dataset, which verify the performance of our system.
Zhuotao Lian, Chunhua Su
AsiaCCS2
2022 WebFed: Cross-platform Federated Learning Framework Based on Web Browser with Local Differential Privacy
abstract
For data isolated islands and privacy issues, federated learning has been extensively invoking much interest since it allows clients to collaborate on training a global model using their local data without sharing any with a third party. However, the existing federated learning frameworks always need sophisticated condition configurations (e.g., sophisticated driver configuration of standalone graphics card like NVIDIA, compile environment) that bring much inconvenience for large-scale development and deployment. To facilitate the deployment of federated learning and the implementation of related applications, we innovatively propose WebFed, a novel browser-based federated learning framework that takes advantage of the browser’s features (e.g., Cross-platform, JavaScript Programming Features) and enhances the privacy protection by applying local differential privacy. Finally, We conduct experiments on heterogeneous devices to evaluate the performance of the proposed WebFed framework.
Zhuotao Lian, Qinglin Yang, Qingkui Zeng, Chunhua Su
ICC4
2022 AoI Optimization for UAV-aided MEC Networks under Channel Access Attacks: A Game Theoretic Viewpoint
abstract
As a promising enabler for edge intelligence, Unmanned Aerial Vehicles (UAVs) are playing a more and more important role in Mobile Edge Computing Networks (MECN), such as ground sensor communication assistance, user data collection, edge computation offloading and remote control services. In UAV-aided MECN, the timeliness of exchange data is a key factor that influences the real-time data-driven decisions at the server-side. Simultaneously, the Age of information (AoI) is also an indicator that reflects the freshness of data in terms of the destination during the communication process. Hence, AoI minimization is a vital goal in the MECN. The most recent work overlooks the possible security issues in the AoI minimization process, especially the revealed channel access attacks (CAAs), which aim to deteriorate network performance from ground to air channels. To overcome this research gap, in this paper, we improve the AoI-oriented channel access problem under CAA from the perspective of game theory. Firstly, a system model with active probability consideration is established to obtain a MECN-based AoI indicator under CAA. Subsequently, by utilizing Ordinary Potential Game (OPG), we formulate the AoI-based channel access optimization problem. Then, to reach the Nash Equilibrium (NE) of the OPG, a learning algorithm called Distributed Channel Access Strategy Determination (DCASD) is proposed to determine the channel access strategies. Finally, we conduct experiments under different parameters to present the better performance of our algorithm as compared with related work.
Yaoqi Yang, Weizheng Wang 0001, Renhui Xu, Gautam Srivastava 0001, Mamoun Alazab, G. Thippa Reddy, Chunhua Su
ICC7
2022 Secure Collaboration Between Consortiums in Permissioned Blockchains
Juzheng Huang, Qiang Tang 0005, Chunhua Su, Na Ruan
ProvSec3
2022 CNN- and GAN-based classification of malicious code families: A code visualization approach
abstract
Malicious code attacks have severely hindered the current development of the Internet technologies. Once the devices are infected with virus, the damages to companies and users are unpredictable. Although researchers have developed malware detection methods, the analysis result still cannot achieve the desired accuracy due to complicated malicious code families and fast-growing variants. In this paper, to solve this problem, we combine Convolutional Neural Networks (CNNs) with Generative Adversarial Networks (GANs) to design an efficient and accurate malware detection method. First, we implement a code visualization method and utilize GAN to generate more samples of malicious code variants in the role of data augmentation. Then, the lightweight AlexNet originated from CNN to classify malware families. Finally, simulation experiments are conducted to evaluate that our CNN plus GAN model can achieve a higher classification accuracy (i.e., 97.78%) compared with some related work.
Weizheng Wang 0001, Yaoqi Yang, Dequan Xu, Chunhua Su
Int. J. Intell. Syst.6
2022 Blockchain and PUF-Based Lightweight Authentication Protocol for Wireless Medical Sensor Networks
abstract
Due to the emergence of heterogeneous Internet of Medical Things (IoMT) (e.g., wearable health devices, smartwatch monitoring, and automated insulin delivery systems), large volumes of patient data are dispatched to central cloud servers for disease analysis and diagnosis. Although this direct mode brings a lot of convenience for both patients and medical professionals (MPs), the open communication channel between them also incurs several security and privacy issues, such as man-in-the-middle attacks, eavesdropping attacks, and tracking attacks. Based on the unsolved challenges in wireless medical sensor networks (WMSNs), several researchers have proposed various authentication and key agreement (AKA) protocols for this type of healthcare system recently. However, most of these protocols do not perceive physical-layer security and over-centralized server problem in WMSN. In this article, to address these two open problems, we propose a lightweight and reliable authentication protocol for WMSN, which is composed of cutting-edge blockchain technology and physically unclonable functions (PUFs). In addition, a fuzzy extractor scheme is introduced to deal with biometric information. Subsequently, two security evaluation methods are used to prove the high reliability of our proposed scheme. Finally, performance evaluation experiments illustrate that the proposed mutual authentication protocol requires the least computation and communication cost among the compared schemes.
Weizheng Wang 0001, Qiu Chen, Zhimeng Yin 0001, Gautam Srivastava 0001, G. Thippa Reddy, Fawaz Alsolami 0001, Chunhua Su
IEEE Internet Things J.7
2022 A Physical-Layer Key Generation Approach Based on Received Signal Strength in Smart Homes
abstract
Due to the characteristics of wireless network transmission, smart home devices are vulnerable to malicious attacks. Malicious attackers can not only intercept the transmission data of smart home devices to grasp the user’s personal privacy information but also can eavesdrop the transmission between devices to forge the user’s legal information. These attacks have brought great security risks to people’s daily lives. In order to ensure the security of transmitted data, establishing keys for smart home devices is necessary. In this article, an adaptive physical-layer key generation scheme based on received signal strength (RSS) is proposed in Smart Homes. The scheme performs group quantization and adaptive quantization on the collected RSS measurements. The design of group quantization improves the randomness of the generated keys and makes 0 and 1 in generated keys more evenly distributed. The advantage of adaptive quantization is to design adaptive quantization intervals. The smart home devices can select the appropriate quantized reference levels according to the RSS measurements in different scenarios. In order to verify the practicability of the key generation scheme, we analyze the performance of the proposed scheme in static and dynamic scenarios. In addition, this scheme is compared with other key generation schemes from various performance indicators. The comparison results show that our scheme is better than other schemes in terms of randomness.
Yuexin Zhang, Xinyi Huang 0001, Yang Xiang 0001, Chunhua Su
IEEE Internet Things J.5
2022 BSIF: Blockchain-Based Secure, Interactive, and Fair Mobile Crowdsensing
abstract
Given the explosive growth of portable devices, mobile crowdsensing (MCS) is becoming an essential approach that fully utilizes pervasive idle resources to accomplish sensing tasks. The traditional MCS relies on the centralized server for task handle is susceptible to a single point of failure. Targeting this security issue, researchers have proposed a series of blockchain-based MCS. However, nodes in the blockchain suffer from high computation cost for data processing. Simultaneously, most blockchain-based MCS systems lack an efficient incentive mechanism for service requesters and workers. In this work, we integrate the smart contract and mobile devices to establish a secure, interactive, and fair blockchain-based MCS system called BSIF. To prevent illegitimate participants, BSIF requests all users to verify their identities using private keys from the registration phase. In the case of worker location privacy leakage, the location-based symmetric key generator is adopted to coordinate a session key for target range worker selection. Besides, we transfer the data evaluation process to the requester side (e.g., a personal computer), reducing computation cost in the blockchain nodes. Due to the homomorphic feature of the Paillier Cryptosystem and common interest, the requester cannot violate the directives from the blockchain. Subsequently, the Stackelberg game is adopted to investigate the participation level of the workers and the fair reward mechanism for the requesters to achieve a dynamic balance. Finally, the security analysis and performance evaluation demonstrate that our BSIF can defend against possible adversaries while significantly cutting overhead and giving participants the utmost incentive.
Weizheng Wang 0001, Yaoqi Yang, Zhimeng Yin 0001, Kapal Dev, Xiaokang Zhou, Xingwang Li 0001, Nawab Muhammad Faseeh Qureshi, Chunhua Su
IEEE J. Sel. Areas Commun.8
2022 Guest Editorial: Security and Privacy Issues in Industry 4.0 Applications
abstract
The papers in this special section focus on security and privacy issues associated with Industry 4.0. In 2011, a group of delegates from business and academia, and politics in German initially proposed the conception of the Fourth Industrial Revolution (or Industry 4.0), which aims to improve the competitive ability in the manufacturing industry of their country. Along with the emergence of the Industry 4.0 term, people started introspecting the existing shortcomings in contemporary industrial society. Especially, the technologies of the past generations cannot maintain data explosive requirements in the Internet and telecommunication industry and fuse real-time data, which would increase waste and reduce productivity and overall equipment effectiveness. Industry 4.0 recognizes the importance of this issue and makes full use of large-scale machine-to-machine communication and the Internet of things (IoT) to increase automation, improve communication, and self-monitoring and diagnose issues without human intervention, finally transforming traditional manufacturing and industrial practices into a modern smart organization. However, with the rapid growth of devices, security and privacy issues rise to the surface. A mass amount of data frequently exchanged in the public channel will draw the attention of some people with evil intentions. Moreover, the resource-limited devices without strong cryptographic assurance would be compromised and hacked by adversaries. Hence, assuring the authenticity, integrity, and nonrepudiation of these industrial IoT data is a hot issue for industry 4.0 at present.
Mamoun Alazab, G. Thippa Reddy, Chunhua Su
IEEE Trans. Ind. Informatics3
2022 Blockchain-Based Reliable and Efficient Certificateless Signature for IIoT Devices
abstract
Nowadays, the Industrial Internet of Things (IIoT) has remarkably transformed our personal lifestyles and society operations into a novel digital mode, which brings tremendous associations with all walks of life, such as intelligent logistics, smart grid, and smart city. Moreover, with the rapid increase of IIoT devices, a large amount of data is swapped between heterogeneous sensors and devices every moment. This trend increases the risk of eavesdropping and hijacking attacks in communication channels, so maintaining data privacy and security becomes two notable concerns at present. Recently, based on the mechanism of the Schnorr signature, a more secure and lightweight certificateless signature (CLS) protocol is popular for the resource-constrained IIoT protocol design. Nevertheless, we found most of the existing CLS schemes are susceptible to several common security weaknesses such as man-in-the-middle attacks, key generation center compromised attacks, and distributed denial of service attacks. To tackle the challenges mentioned previously, in this article, we propose a novel pairing-free certificateless scheme that utilizes the state-of-the-art blockchain technique and smart contract to construct a novel reliable and efficient CLS scheme. Then, we simulate the Type-I and Type-II adversaries to verify the trustworthiness of our scheme. Security analysis as well as performance evaluation outcomes prove that our design can hold more reliable security assurance with less computation cost (i.e., reduced by around 40.0% at most) and communication cost (i.e., reduced by around 94.7% at most) than other related schemes.
Weizheng Wang 0001, Mamoun Alazab, G. Thippa Reddy, Chunhua Su
IEEE Trans. Ind. Informatics6
2022 On the Design of Blockchain-Based ECDSA With Fault-Tolerant Batch Verification Protocol for Blockchain-Enabled IoMT
abstract
The blockchain-enabled internet of medical things (IoMT) is an emerging paradigm that could provide strong trust establishment and ensure the traceability of data sharing in the IoMT networks. One of the fundamental building blocks for Blockchain is Elliptic Curve Digital Signature Algorithm (ECDSA). Nevertheless, when processing a large number of transactions, the verification of multiple signatures will incur cumbersome overhead to the nodes in Blockchain. Although batch verification is able to provide a promising approach that verifies multiple signatures simultaneously and efficiently, the upper bound of batch size is limited to small-scale and the efficiency will drop rapidly as the batch size grows in the state-of-the-art ECDSA batch schemes. Meanwhile, most of the existing researches only focus on improving the efficiency of batch verification algorithms in various cryptosystem while ignoring the identification of invalid signatures, which could cause severe performance degradation when the batch verification fails. Motivated by these observations, this paper proposes an efficient and large-scale batch verification scheme with group testing technology based on ECDSA. The application of the presented protocols in Bitcoin and Hyperledger Fabric has been analyzed as supportive and effective. When the batch verification returns a false result, we utilize group testing technology to improve the efficiency of identifying invalid signatures. Comprehensive simulation results demonstrate that our protocol outperforms the related ECDSA batch verification schemes.
Hu Xiong, Chuanjie Jin, Mamoun Alazab, Kuo-Hui Yeh, Hanxiao Wang 0002, G. Thippa Reddy, Weizheng Wang 0001, Chunhua Su
IEEE J. Biomed. Health Informatics8
2022 Age Efficient Optimization in UAV-Aided VEC Network: A Game Theory Viewpoint
abstract
The timeless and efficient vehicle data transmission are the two common requirements for the Internet of Vehicles (IoV), especially the Unnamed Aircraft Vehicle (UAV)-aided Vehicular Edge Computing (VEC) network. Moreover, since the Age of Information (AoI) performance greatly influences these two indicators, data quality should be guaranteed in vehicle communication. However, few researchers pay attention to the AoI performance optimization issue regarding wireless resource constraint, transmission interference, and vehicle cooperation in recent years. To close this research gap, we propose an AoI-oriented channel access strategy in the UAV-aided VEC network from the game theory viewpoint. Firstly, the UAV-aided VEC network model and edge computing-based AoI expression are established and derived in the closed form, respectively. Subsequently, we transform the AoI minimization problem into an AoI-based channel access issue from the game theory viewpoint. Moreover, the stochastic learning-based algorithm is proposed to find the Nash Equilibrium (NE) solution of the formulated problem. Finally, simulation results evaluate the correctness and effectiveness of the proposed algorithms, where our scheme can achieve the better AoI value compared with baselines.
Yaoqi Yang, Weizheng Wang 0001, Lu Zhou 0002, Tu N. Nguyen 0001, Chunhua Su
IEEE Trans. Intell. Transp. Syst.6
2022 Efficient Encrypted Data Search With Expressive Queries and Flexible Update
abstract
Outsourcing encrypted data to cloud servers that has become a prevalent trend among Internet users to date. There is a long list of advantages on data outsourcing, such as the reduction cost of local data management. How to securely operate encrypted data (remotely), however, is the top-rank concern over data owner. Lianget al.proposed a novel encrypted cloud-based data share and search system without loss of privacy. The system allows users to flexibly search and share encrypted data as well as updating keyword field. However, the search complexity of the system is of extreme inefficiency,$O(n d)$, where$d$is the total number of system files and$n$is the size of query formula. This article, for the first time, leverages the “oblivious cross search” technology in public key searchable encryption context to reduce the search complexity toonly$O(nf(w))$, where$f(w)$is the number of files embedded with the “least frequent keyword”$w$. The new scheme maintains efficient encrypted data share and keyword field update as well. This article further revisits the security models for payload security, keyword privacy and search token privacy (i.e., search pattern privacy) and meanwhile, presents security and efficiency analysis for the new scheme.
Jianting Ning, Jiageng Chen, Kaitai Liang, Joseph K. Liu, Chunhua Su, Qianhong Wu
IEEE Trans. Serv. Comput.5
2021 ALRS: An Adversarial Noise Based Privacy-Preserving Data Sharing Mechanism
Jikun Chen, Ruoyu Deng, Na Ruan, Yao Liu 0007, Chunhua Su
ACISP7
2021 COFEL: Communication-Efficient and Optimized Federated Learning with Local Differential Privacy
abstract
Federated learning can collaboratively train a global model without gathering clients’ private data. Many works focus on reducing communication cost by designing kinds of client selection method or averaging algorithm. But they all consider whether the client will participant or not, and the training time could not be reduced as data size of update for each client is not changed. We proposed COFEL, a novel federated learning system which can both reduce the communication time by layer-based parameter selection and enhance the privacy protection by applying local differential privacy mechanism on the selected parameters. We present COFEL-AVG algorithm for global aggregation and designed layer-based parameter selection method which can select the valuable parameters for global aggregation to optimize the communication and training process. And it can reduce the update data size as only selected part will be transferred. We compared with traditional federated learning system and CMFL which also applies a parameter selection method but model-based and performed experiments on MNIST, Fashion-MNIST and CIFAR-10 to verify the effectiveness of COFEL. The results denoted that it can improve at most 22.8% accuracy compared with CMFL on CIFAR-10 and reduce around 20% and 48% training time to reach an accuracy of 0.85 compared with traditional FL and CMFL on Fashion-MNIST dataset.
Zhuotao Lian, Weizheng Wang 0001, Chunhua Su
ICC3
2021 A Provenance-Aware Distributed Trust Model for Resilient Unmanned Aerial Vehicle Networks
abstract
An unmanned aerial vehicle (UAV) network is an emerging industrial IoT network for collaborative UAV communication and management. The open architecture and dynamic topology, which provide functional benefits, unfortunately make UAVNs more vulnerable to a variety of attacks. In UAVNs, malicious nodes not only eavesdrop the communications between UAV nodes but also attempt to attack the entire network by injecting or modifying messages. This work proposes a provenance-aware distributed trust model, named UAV-pro, for UAVNs that aim to achieve accurate peer-to-peer trust assessment and maximize the delivery of correct messages received by destination nodes while minimizing the message delay and communication cost under resource-constrained network environments. Provenance refers to the history of ownership of messages transmitted on the network. The behavior of message creators and operators can be effectively evaluated based on message integrity, then generate the observational evidence. We collect the observational evidence for distributed trust evaluation, then identify malicious nodes in the network and isolate them from the network. UAVN-pro takes a data-driven approach to reduce resource consumption in the presence of selfish or malicious nodes while ensuring the safe transmission of data by digital signature technology. The experimental results show that UAVN-pro works are compatible with the existing UAV network routing protocols, and can effectively identify attacks, such as the black hole, gray hole, message modification, fake recommendation, and fake identity in UAV networks. UAVN-pro is superior to the existing security model in terms of detection rate, delivery rate, and system energy consumption in most cases.
Chunpeng Ge 0001, Lu Zhou 0002, Gerhard P. Hancke 0002, Chunhua Su
IEEE Internet Things J.4
2021 Block-Sparse Coding-Based Machine Learning Approach for Dependable Device-Free Localization in IoT Environment
abstract
Device-free localization (DFL) locates targets without equipping with wireless devices or tag under the Internet-of-Things (IoT) architectures. As an emerging technology, DFL has spawned extensive applications in the IoT environment, such as intrusion detection, mobile robot localization, and location-based services. Current DFL-related machine learning (ML) algorithms still suffer from low localization accuracy and weak dependability/robustness because the group structure has not been considered in their location estimation, which leads to an undependable process. To overcome these challenges, we propose in this work a dependable block-sparse scheme by particularly considering the group structure of signals. An accurate and robust ML algorithm named block-sparse coding with the proximal operator (BSCPO) is proposed for DFL. In addition, a severe Gaussian noise is added in the original sensing signals for preserving network-related privacy as well as improving the dependability of the model. The real-world data-driven experimental results show that the proposed BSCPO achieves robust localization and signal-recovery performance even under severely noisy conditions and outperforms state-of-the-art DFL methods. For single-target localization, BSCPO retains high accuracy when the signal-to-noise ratio exceeds -10 dB. BSCPO is also able to localize accurately under most multitarget localization test cases.
Lingjun Zhao, Huakun Huang, Chunhua Su, Shuxue Ding, Huawei Huang, Zhiyuan Tan 0001, Zhenni Li
IEEE Internet Things J.3
2021 A lightweight multi-party authentication in insecure reader-server channel in RFID-based IoT
Mohammad Saiful Islam Mamun, Atsuko Miyaji, Rongxing Lu, Chunhua Su
Peer-to-Peer Netw. Appl.4
2021 Secure and efficient mutual authentication protocol for smart grid under blockchain
Weizheng Wang 0001, Huakun Huang, Lejun Zhang, Chunhua Su
Peer-to-Peer Netw. Appl.4
2021 ANCS: Automatic NXDomain Classification System Based on Incremental Fuzzy Rough Sets Machine Learning
abstract
Botmasters generate a large number of malicious algorithmically generated domains (mAGDs) through domain generation algorithms (DGAs) to infect a large number of hosts on a network, which creates inconvenience in people's network lives. The workload of detecting mAGDs by collecting the responses of the domain name system (DNS) is considerable. In this article, we propose a system named the automatic NXDomain classification system (ANCS) that can automatically identify and classify the nonexistent domain (NXD) as benign or malicious by studying the features extracted from benign NXDs (bNXDs) and mAGDs. The ANCS uses online, incremental, and fuzzy rough sets machine learning to improve the time, memory, false positive rate, false negative rate, and accuracy of the detection process. First, an online and incremental algorithm can reduce the training time. Second, the addition of fuzzy rough sets can dynamically adjust the degree of the membership function, optimizing the weight distribution of each feature, and further, improving the classification accuracy. The experimental evaluation shows that the ANCS can reach a very high classification accuracy at a low false positive rate and a low false negative rate, which has good practicability. Moreover, both time and memory are well guaranteed, and the ANCS also has good generalization performance, making up for sensitive points of noisy samples and the lack of nonincremental machine learning.
Liming Fang 0001, Xinyu Yun, Changchun Yin, Weiping Ding 0001, Lu Zhou 0002, Zhe Liu 0001, Chunhua Su
IEEE Trans. Fuzzy Syst.7
2020 How to Model the Bribery Attack: A Practical Quantification Method in Blockchain
Hanyi Sun, Na Ruan, Chunhua Su
ESORICS (2)3
2020 Intelligent Detection Algorithm Against UAVs' GPS Spoofing Attack
abstract
Unmanned Aerial Vehicle (UAV) technology is more and more widely used in the field of civil and military information acquisition. GPS plays the most critical part of UAVs' navigation and positioning. However, since the communication channel of the GPS signals is open, attackers can disguise as real GPS signals to launch GPS spoofing attacks on civilian UAVs. At present, the detection schemes for GPS spoofing attacks can be divided into three categories respectively based on encryption and digital signatures, the characteristics of the GPS signal and various external characteristics of UAVs. However, there are some problems in these methods, such as low computing efficiency, difficulty in equipment upgrading, and limited application scenarios. To solve these problems, we propose a new GPS spoofing attack detection method based on Long Short-Term Memory (LSTM) which is a machine learning algorithm. In order to improve the detection ratio, after the machine learning algorithm, we let the UAVs fly according to the path of a specific shape to accurately detect GPS spoofing attacks. This is also the first time machine learning has been used to detect GPS spoofing attacks. According to our algorithm, we can detect GPS spoofing attacks accurately and quickly in a short time. This paper describes in detail the algorithm we proposed to resist GPS spoofing attacks, and the corresponding experiments are carried out in the simulation environment. The experimental results show that our method can quickly and accurately detect UAV GPS spoofing attacks without requiring upgrades to existing equipment.
Shenqing Wang, Jian Wang 0038, Chunhua Su, Xinshu Ma
ICPADS3
2020 Deep Reinforcement Learning for Optimal Resource Allocation in Blockchain-based IoV Secure Systems
abstract
Driven by the advanced technologies of vehicular communications and networking, the Internet of Vehicles (IoV) has become an emerging paradigm in smart world. However, privacy and security are still quite critical issues for the current IoV system because of various sensitive information and the centralized interaction architecture. To address these challenges, a decentralized architecture is proposed to develop a blockchain-supported IoV (BS-IoV) system. In the BS-IoV system, the Roadside Units (RSUs) are redesigned for Mobile Edge Computing (MEC). Except for information collection and communication, the RSUs also need to audit the data uploaded by vehicles, packing data as block transactions to guarantee high-quality data sharing. However, since block generating is critical resource-consuming, the distributed database will cost high computing power. Additionally, due to the dynamical variation environment of traffic system, the computing resource is quite difficult to be allocated. In this paper, to solve the above problems, we propose a Deep Reinforcement Learning (DRL) based algorithm for resource optimization in the BS-IoV system. Specifically, to maximize the satisfaction of the system and users, we formulate a resource optimization problem and exploit the DRL-based algorithm to determine the allocation scheme. The evaluation of the proposed learning scheme is performed in the SUMO with Flow, which is a professional simulation tool for traffic simulation with reinforcement learning functions interfaces. Evaluation results have demonstrated good effectiveness of the proposed scheme.
Hongzhi Xiao, Chen Qiu 0007, Qinglin Yang, Huakun Huang, Junbo Wang 0001, Chunhua Su
MSN6
2020 CCBRSN: A System with High Embedding Capacity for Covert Communication in Bitcoin
Weizheng Wang 0001, Chunhua Su
SEC2
2020 BlockSLAP: Blockchain-based Secure and Lightweight Authentication Protocol for Smart Grid
abstract
Due to intelligent electronic management, the smart grid has recently played a significant role in modern energy infrastructure. However, along with widespread deployment of the smart grid, many potential security threats (e.g., impersonation attack, replay attack, man-in-the-middle attack) rise to the surface. To defend against these possible attacks, numerous cryptography-based authentication schemes have been proposed for the smart grid. Most of the schemes investigate the secret key distribution problem, but the requirement of decentralized registration authority is neglected. In addition, over-complicated cryptographic primitives also strengthen the burden of authentication system. In contrast with previous researches, our proposed BlockSLAP utilizes cutting-edge blockchain technology as well as smart contract to decentralize the registration authority and reduce the interaction process to 2 steps. Moreover, our protocol is proved secure under computational hard assumption and informal security analysis. Finally, experimental results show that smart grid authentication performance in our protocol has been improved compared to the other existing ECC-related schemes.
Weizheng Wang 0001, Huakun Huang, Lejun Zhang, Chen Qiu 0007, Chunhua Su
TrustCom6
2020 A privacy preserving two-factor authentication protocol for the Bitcoin SPV nodes
Lu Zhou 0002, Chunpeng Ge 0001, Chunhua Su
Sci. China Inf. Sci.3
2020 GADM: Manual fake review detection for O2O commercial platforms
Na Ruan, Ruoyu Deng, Chunhua Su
Comput. Secur.3
2020 Am I eclipsed? A smart detector of eclipse attacks for Ethereum
Guangquan Xu, Bingjiang Guo, Chunhua Su, James Xi Zheng, Kaitai Liang, Duncan S. Wong, Hao Wang 0003
Comput. Secur.3
2020 Energy-Efficient and Privacy-Preserving Data Aggregation Algorithm for Wireless Sensor Networks
abstract
Privacy-preserving data aggregation is a kind of fundamental and essential algorithm for wireless sensor networks. However, the existing aggregation algorithms consume a large amount of energy to assure sensory data security. In this article, we propose an energy-efficient and privacy-preserving data aggregation algorithm (EPDA). We organize a sensor network into a tree and connect the leaf nodes of the tree to form many chains. EPDA requires only the data sensed by the tail nodes of the chains to be sliced to ensure privacy. Also, EPDA significantly decreases energy consumption and prolongs the lifetime of the network. We compare our scheme with the existing schemes through theoretical analysis and simulations. The analysis and simulation results show that EPDA outperforms the existing schemes.
Lu Zhou 0002, Chunpeng Ge 0001, Chunhua Su
IEEE Internet Things J.4
2020 A physiological and behavioral feature authentication scheme for medical cloud based on fuzzy-rough core vector machine
Liming Fang 0001, Changchun Yin, Lu Zhou 0002, Yang Li 0103, Chunhua Su, Jinyue Xia
Inf. Sci.5
2020 A secure and efficient certificateless batch verification scheme with invalid signature identification for the internet of things
Hu Xiong, Yan Wu 0014, Chunhua Su, Kuo-Hui Yeh
J. Inf. Secur. Appl.3
2020 Design and application of a personal credit information sharing platform based on consortium blockchain
Rong Tan, Chunhua Su, Wen Si
J. Inf. Secur. Appl.3
2020 Leakage-resilient biometric-based remote user authentication with fuzzy extractors
Yangguang Tian, Yingjiu Li, Binanda Sengupta, Nan Li 0007, Chunhua Su
Theor. Comput. Sci.5
2020 Indoor device-free passive localization with DCNN for location-based services
Lingjun Zhao, Chunhua Su, Zeyang Dai, Huakun Huang, Shuxue Ding, Xinyi Huang 0001
J. Supercomput.2
2019 CAVAEva: An Engineering Platform for Evaluating Commercial Anti-malware Applications on Smartphones
Weizhi Meng 0001, Chunhua Su, Kim-Kwang Raymond Choo
Inscrypt3
2019 Practical Bayesian Poisoning Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Kim-Kwang Raymond Choo, Chunhua Su
ESORICS (1)5
2019 Measuring Security of Symmetric Encryption Schemes Against On-the-Fly Side-Channel Key-Recovery Attacks
Bagus Santoso, Yasutada Oohama, Chunhua Su
NSS3
2019 An Efficient Vulnerability Detection Model for Ethereum Smart Contracts
Jingjing Song, Haiwu He, Zhuo Lv, Chunhua Su, Guangquan Xu, Wei Wang 0012
NSS4
2019 Security analysis and new models on the intelligent symmetric key encryption
Lu Zhou 0002, Jiageng Chen, Chunhua Su, Marino Anthony James
Comput. Secur.4
2019 Polynomial-based modifiable blockchain structure for removing fraud transactions
Lichen Cheng, Jiqiang Liu, Chunhua Su, Kaitai Liang, Guangquan Xu, Wei Wang 0012
Future Gener. Comput. Syst.3
2019 Lightweight IoT-based authentication scheme in cloud computing circumstance
Lu Zhou 0002, Xiong Li 0002, Kuo-Hui Yeh, Chunhua Su, Wayne Chiu
Future Gener. Comput. Syst.4
2019 Automatic fine-grained access control in SCADA by machine learning
Lu Zhou 0002, Chunhua Su, Zhen Li 0047, Zhe Liu 0001, Gerhard P. Hancke 0002
Future Gener. Comput. Syst.2
2019 Secure and Efficient K Nearest Neighbor Query Over Encrypted Uncertain Data in Cloud-IoT Ecosystem
abstract
Uncertain data pervades many fields, including environmental monitoring, the monitoring of animal migrations, and urban warfare. Such uncertain data collected by field devices, such as Internet of Things (IoT) and Internet of Battlefield Things (IoBT) devices, may also be encrypted and outsourced to an untrustworthy third party for storage and data sharing such as a cloud server. However, the properties of uncertain data and the complication of operating over encrypted data make the searching schemes more ineffective. In this article, we design an efficient and safe K nearest neighbor (KNN) query scheme for uncertain data stored in semi-trusted cloud servers. We apply the modified homomorphic encryption, which requires two servers to interact and encrypt the uncertain data, and we use the authorized rank method to compute KNN. We protect the security of the data while simultaneously improving the query efficiency. Our detailed security analysis show that our scheme can realize the goal of concealing both the access and the search patterns. Comprehensive experiments are conducted to demonstrate the scheme's performance.
Cheng Guo 0001, Ruhan Zhuang, Chunhua Su, Charles Zhechao Liu, Kim-Kwang Raymond Choo
IEEE Internet Things J.3
2019 Game theoretic security of quantum bit commitment
Lu Zhou 0002, Xin Sun 0001, Chunhua Su, Zhe Liu 0001, Kim-Kwang Raymond Choo
Inf. Sci.3
2019 AI-Driven Cyber Security Analytics and Privacy Protection
abstract
has gone through a rapid development in today's internet connected world.With the wide application of the booming technologies such as the Internet of ings (IoT) and the cloud computing, huge amount of data are generated and collected.While the data can be used to better serve the corresponding business needs, they also pose big challenges for the cyber security and privacy protection.It becomes very di cult if not impossible to discover the malicious behavior among the big data in real time.us, this gives rise to the cyber security solutions which are driven by AI-based technologies, such as machine learning, statistical inference, big data analysis, deep learning, and so on.AIdriven cyber security analytics has already found its applications in the next generation rewall which includes the automatic intrusion detection system, encrypted tra c classi cation, malicious software detection, and so on.In the area of cryptography, AI-driven solution starts to help the researchers optimize the algorithm design and can largely reduce the cryptanalysis e ort such as searching the di erential trails which is crucial in di erential cryptanalysis.
Jiageng Chen, Chunhua Su, Zheng Yan 0002
Secur. Commun. Networks2
2019 Lightweight Implementations of NIST P-256 and SM2 ECC on 8-bit Resource-Constraint Embedded Device
abstract
Elliptic Curve Cryptography (ECC) now is one of the most important approach to instantiate asymmetric encryption and signature schemes, which has been extensively exploited to protect the security of cyber-physical systems. With the advent of the Internet of Things (IoT), a great deal of constrained devices may require software implementations of ECC operations. Under this circumstances, the SM2, a set of public key cryptographic algorithms based on elliptic curves published by Chinese Commercial Cryptography Administration Office, was standardized at ISO in 2017 to enhance the cyber-security. However, few research works on the implementation of SM2 for constrained devices have been conducted. In this work, we fill this gap and propose our efficient, secure, and compact implementation of scalar multiplication on a 256-bit elliptic curve recommended by the SM2, as well as a comparison implementation of scalar multiplication on the same bit-length elliptic curve recommended by NIST. We re-design some existent techniques to fit the low-end IoT platform, namely 8-bit AVR processors, and our implementations evaluated on the desired platform show that the SM2 algorithms have competitive efficiency and security with NIST, which would work well to secure the IoT world.
Lu Zhou 0002, Chunhua Su, Hwajeong Seo
ACM Trans. Embed. Comput. Syst.2
2019 A Lightweight Cryptographic Protocol with Certificateless Signature for the Internet of Things
abstract
The universality of smart-devices has brought rapid development and the significant advancement of ubiquitous applications for the Internet of Things (IoT). Designing new types of IoT-compatible cryptographic protocols has become a more popular way to secure IoT-based applications. Significant attention has been dedicated to the challenge of implementing a lightweight and secure cryptographic protocol for IoT devices. In this study, we propose a lightweight cryptographic protocol integrating certificateless signature and bilinear pairing crypto-primitives. In the proposed protocol, we elegantly refine the processes to account for computation-limited IoT devices during security operations. Rigorous security analyses are conducted to guarantee the robustness of the proposed cryptographic protocol. In addition, we demonstrate a thorough performance evaluation, where an IoT-based test-bed, i.e., the Raspberry PI, is simulated as the underlying platform of the implementation of our proposed cryptographic protocol. The results show the practicability of the proposed protocol.
Lu Zhou 0002, Chunhua Su, Kuo-Hui Yeh
ACM Trans. Embed. Comput. Syst.2
2018 Analysis of Variance of Graph-Clique Mining for Scalable Proof of Work
Hiroaki Anada, Tomohiro Matsushima, Chunhua Su, Weizhi Meng 0001, Junpei Kawamoto, Samiran Bag, Kouichi Sakurai
Inscrypt3
2018 SpamTracer: Manual Fake Review Detection for O2O Commercial Platforms by Using Geolocation Features
Ruoyu Deng, Na Ruan, Ruidong Jin, Weijia Jia 0001, Chunhua Su, Dandan Xu
Inscrypt6
2018 CPMap: Design of Click-Points Map-Based Graphical Password Authentication
Weizhi Meng 0001, Fei Fei, Lijun Jiang, Zhe Liu 0001, Chunhua Su, Jinguang Han
SEC5
2018 Special Issue on Advanced Persistent Threat
Jiageng Chen, Chunhua Su, Kuo-Hui Yeh, Moti Yung
Future Gener. Comput. Syst.2
2018 Stag hunt and trust emergence in social networks
Lu Zhou 0002, Chunhua Su, Xin Sun 0001, Xishun Zhao, Kim-Kwang Raymond Choo
Future Gener. Comput. Syst.2
2018 Towards practical white-box lightweight block cipher implementations for IoTs
Lu Zhou 0002, Chunhua Su, Yamin Wen
Future Gener. Comput. Syst.2
2018 OTP-IoT: An ownership transfer protocol for the Internet of Things
Mohammad Saiful Islam Mamun, Chunhua Su, Anjia Yang, Atsuko Miyaji, Ali A. Ghorbani 0001
J. Inf. Secur. Appl.2
2017 DABEHR: Decentralized Attribute-Based Electronic Health Record System with Constant-Size Storage Complexity
Kaitai Liang, Chunhua Su, Wei Wu 0001
GPC3
2017 Automatic Encryption Schemes Based on the Neural Networks: Analysis and Discussions on the Various Adversarial Models (Short Paper)
Marino Anthony James, Jiageng Chen, Chunhua Su, Jinguang Han
ISPEC4
2017 Exploring Energy Consumption of Juice Filming Charging Attack on Smartphones: A Pilot Study
Lijun Jiang, Weizhi Meng 0001, Yu Wang 0017, Chunhua Su, Jin Li 0002
NSS4
2017 Provable Secure Post-Quantum Signature Scheme Based on Isomorphism of Polynomials in Quantum Random Oracle Model
Bagus Santoso, Chunhua Su
ProvSec2
2017 Variable message encryption through blockcipher compression function
abstract
Summary A constrained device is an emerging technology that has enormous applications in our daily life such as access control, inventory control, luggage tracking, bar‐code reader, and IoT. However, it has certain drawbacks of low memory and less computing power. Thus, one of the cracking challenges is to provide efficient and secure cryptographic solution for the constrained device in the aspect of security issue. An (n,n) blockcipher‐based cryptographic compression function is applicable to provide provable security to the constrained device. Though, there are many constructions of (n,n) blockcipher such as MDC‐2, MDC‐4, MJH, Bart‐12, and SKS‐15. However, most of the familiar schemes are not suitable for short and variable message encryption without padding because of their internal structures. Furthermore, the security margin is provided based on blocklength rather than the flexible size of message. In this paper, we present two different (n,n) blockcipher compression function schemes. The first scheme (FS) satisfies better efficiency such as less call of blockcipher, less key scheduling, and higher efficiency rate. On the contrary, the second scheme (SS) has upper security bound. Moreover, both of the schemes are suitable for small and variable message encryption (message size = tn|t < 1,n:blocklength), which is handy for the constrained device. The collision and preimage security bound of the FS are O(2tn/2) and O(2tn). In addition, the SS's collision resistance and preimage resistance are bounded by O(2tn) and O(22tn). Moreover, the efficiency rate of the proposed two schemes are respectively t and t/3. The numbers of key scheduling are 2 for the constructions of FS and SS. We use two calls of blockcipher in the FS. On the contrary, three calls of blockcipher are used in the SS. Copyright © 2016 John Wiley & Sons, Ltd.
Jiageng Chen, Mazumder Rashed, Atsuko Miyaji, Chunhua Su
Concurr. Comput. Pract. Exp.4
2017 A simple authentication encryption scheme
abstract
Summary An authentication encryption (AE) scheme satisfies to transfer an authenticated data between 2 parties or more. There are vast applications of the AE such as access control, encryption, enhancing trust between multiple parties, and assure the originality of a message. However, the main challenge of the AE is to maintain low‐cost features for its construction. Furthermore, there is another emerging issue of Internet of Things (IoT) in the field of data and network communication. The numbers of application of the IoT are increasing expeditiously, where various kinds of device have been used such as IoT‐end device, constrained device, and RfID. Moreover, the main challenge of the IoT‐end devices and resource constrained devices is to keep a certain level of security bound including minimum cost. However, the IoT‐end devices, resource constrained devices, and RfID have lack of resources such as memory, power, and processors. Interestingly, the AE can play a vital role between data acquisition (sensors, actuators) and data aggregation of usual platform of the IoT. Thus, the construction of the AE should satisfy the properties of low‐cost, least resources, and less operating‐time. Though, there are many familiar constructions of AE such as OTR, McOE, POE, OAE, APE, COPE, CLOC, and SILK but most of the schemes depend on the features of nonce and associate data. In the aspect of security, the usage of nonce and associated data are adequate. However, these 2 features increase the overhead cost. Therefore, we propose a simple construction of IV‐based AE where blockcipher compression function is used as encryption function. Our proposed scheme's efficiency‐rate is 1 with reasonable privacy‐security bound. In addition, it can encrypt arbitrary length of message in each iteration without padding.
Mazumder Rashed, Atsuko Miyaji, Chunhua Su
Concurr. Comput. Pract. Exp.3
2017 Special issue on Secure Computation on Encrypted Data
Jiageng Chen, Debiao He, Chunhua Su, Zhe Xia
J. Inf. Secur. Appl.3
2017 Towards Accurate Statistical Analysis of Security Margins: New Searching Strategies for Differential Attacks
abstract
In today's world of the internet, billions of computer systems are connected to one another in a global network. The internet provides an unsecured channel in which hundreds of terabytes of data is being transmitted daily. Computer and software systems rely on encryption algorithms such as block ciphers to ensure that sensitive data remains confidential and secure. However, adversaries can leverage the statistical behavior of underlying ciphers to recover encryption keys. Accurate evaluation of the security margins of these encryption algorithms remains to be a big challenge. In this paper, we tackle this issue by introducing several searching strategies based on differential cryptanalysis. By clustering differential paths, the searching algorithm derives more accurate distinguishers as compared to examining individual paths, which in turn provides a more accurate estimation of cipher security margins. We verify the effectiveness of this technique on ciphers with the generalized Feistel and SPN structures, whereby the best distinguishers for each of the investigated ciphers were obtained by discovering clusters with thousands of paths. With the KATAN block cipher family as a test case, we also show how to apply the searching algorithm alongside other cryptanalysis techniques such as the boomerang attack and related-key model to obtain the best cryptanalytic results. This also depicts the flexibility of the proposed searching scheme, which can be tailored to improve upon other differential attack variants. In short, the proposed searching strategy realizes an automated security evaluation tool with higher accuracy compared to previous techniques. In addition, it is applicable to a wide range of encryption schemes which makes it a flexible tool for both academic research and industrial purposes.
Jiageng Chen, Je Sen Teh, Zhe Liu 0001, Chunhua Su, Azman Samsudin, Yang Xiang 0001
IEEE Trans. Computers4
2017 Universally Composable RFID Mutual Authentication
abstract
Universally Composable (UC) framework provides the strongest security notion for designing fully trusted cryptographic protocols, and it is very challenging on applying UC security in the design of RFID mutual authentication protocols. In this paper, we formulate the necessary conditions for achieving UC secure RFID mutual authentication protocols which can be fully trusted in arbitrary environment, and indicate the inadequacy of some existing schemes under the UC framework. We define the ideal functionality for RFID mutual authentication and propose the first UC secure RFID mutual authentication protocol based on public key encryption and certain trusted third parties which can be modeled as functionalities. We prove the security of our protocol under the strongest adversary model assuming both the tags' and readers' corruptions. We also present two (public) key update protocols for the cases of multiple readers: one uses Message Authentication Code (MAC) and the other uses trusted certificates in Public Key Infrastructure (PKI). Furthermore, we address the relations between our UC framework and the zero-knowledge privacy model proposed by Deng et al. [1].
Chunhua Su, Bagus Santoso, Yingjiu Li, Robert H. Deng, Xinyi Huang 0001
IEEE Trans. Dependable Secur. Comput.1
2017 Recursive Matrix Oblivious RAM: An ORAM Construction for Constrained Storage Devices
abstract
Oblivious random access machine (ORAM) constructions can be used to hide a client's access pattern from a trusted but curious storage server. The privacy provided comes at the cost of increasing communication overhead, storage overhead, and computation overhead of the system. Recursive matrix-based ORAM (RM-ORAM) is a new ORAM construction, which is designed for constrained storage space devices. RM-ORAM significantly reduces the client storage usage by using recursion, while the computational and bandwidth overhead are slightly increased as a tradeoff. However, it can achieve better overall asymptotic performance than other existing ORAM schemes, e.g., recursive Path ORAM. In this paper, we present the construction and its theoretical analysis. In addition, we present how to select the appropriate number of data blocks, which are being downloaded per level of recursion and the appropriate size of reserved space on the client. We provide theoretical security and performance analysis, as well as experimental results to illustrate how RM-ORAM satisfies security requirements and provides improved performance compared with other ORAM schemes.
Xinyi Huang 0001, Atsuko Miyaji, Chunhua Su, Karin Sumongkayothin, Komwut Wipusitwarakun
IEEE Trans. Inf. Forensics Secur.4
2016 Improved (related-key) Attacks on Round-Reduced KATAN-32/48/64 Based on the Extended Boomerang Framework
Jiageng Chen, Je Sen Teh, Chunhua Su, Azman Samsudin
ACISP (2)3
2016 Secure and Traceable Framework for Data Circulation
Kaitai Liang, Atsuko Miyaji, Chunhua Su
ACISP (1)3
2016 Efficient Multi-Function Data Sharing and Searching Mechanism for Cloud-Based Encrypted Data
abstract
Outsourcing a huge amount of local data to remote cloud servers that has been become a significant trend for industries. Leveraging the considerable cloud storage space, industries can also put forward the outsourced data to cloud computing. How to collect the data for computing without loss of privacy and confidentiality is one of the crucial security problems. Searchable encryption technique has been proposed to protect the confidentiality of the outsourced data and the privacy of the corresponding data query. This technique, however, only supporting search functionality, may not be fully applicable to real-world cloud computing scenario whereby secure data search, share as well as computation are needed. This work presents a novel encrypted cloud-based data share and search system without loss of user privacy and data confidentiality. The new system enables users to make conjunctive keyword query over encrypted data, but also allows encrypted data to be efficiently and multiply shared among different users without the need of the "download-decrypt-then-encrypt" mode. As of independent interest, our system provides secure keyword update, so that users can freely and securely update data's keyword field. It is worth mentioning that all the above functionalities do not incur any expansion of ciphertext size, namely, the size of ciphertext remains constant during being searched, shared and keyword-updated. The system is proven secure and meanwhile, the efficiency analysis shows its great potential in being used in large-scale database.
Kaitai Liang, Chunhua Su, Jiageng Chen, Joseph K. Liu
AsiaCCS2
2016 Security and experimental performance analysis of a matrix ORAM
abstract
Oblivious RAM can hide a client's access pattern from an untrusted storage server. However current ORAM schemes incur a large communication overhead and/or client storage overhead, especially as the server storage size grows. We have proposed a matrix-based ORAM, M-ORAM, that makes the communication overhead independent of the server size. This requires selecting a height of the matrix; we present how to select the height to match the functionality of the well-known Path ORAM. We then given both theoretical models and experimental results that show M-ORAM can achieve a lower communication overhead than Path ORAM, without a significant increase in maximum client storage overhead.
Atsuko Miyaji, Chunhua Su, Karin Sumongkayothin
ICC3
2016 Privacy-Preserving Mining of Association Rules for Horizontally Distributed Databases Based on FP-Tree
Yaoan Jin, Chunhua Su, Na Ruan, Weijia Jia 0001
ISPEC2
2016 Improved handover authentication and key pre-distribution for wireless mesh networks
abstract
Summary Ticket‐based authentication is a critical technology to secure wireless mesh networks (WMN), which enable efficient communication among laptops, cell phones and other wireless devices. In this paper, we provide a new design of handoff authentication for WMN to reduce the delay caused by handoff. Our major improvement is on the key pre‐distribution for handoff authentication. We apply the attribute‐based encryption to encrypt key pre‐distribution messages for neighbor mesh routers. As a result, key pre‐distribution has constant computation and communication costs, which are independent of the number of neighbor mesh routers. Another advantage of our design is that it can perform immediate handoff authentication once the login authentication is complete, even before key pre‐distribution messages reach the foreign mesh router. The security of our handoff authenticator protocol is also improved by employing home mesh router's digital signature in the handoff ticket and key pre‐distribution messages. Our scheme can efficiently thwart forgery attacks. The proposed scheme provides an efficient and secure solution that meets the requirements of WMN in the era of Big Data. Copyright © 2015 John Wiley & Sons, Ltd.
Xu Yang 0002, Xinyi Huang 0001, Jinguang Han, Chunhua Su
Concurr. Comput. Pract. Exp.4
2015 Accurate Estimation of the Full Differential Distribution for General Feistel Structures
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Je Sen Teh
Inscrypt3
2015 Improved Differential Characteristic Searching Methods
abstract
The success probability of differential and linear cryptanalysis against block ciphers heavily depend on finding differential or linear paths with high statistical bias compared with uniform random distribution. For large number of rounds, it is not a trivial task to find such differential or linear paths. Matsui first investigated this problem and proposed a solution based on a branch and bound algorithm in 1994. Since then, the research on finding good concrete differential or linear path did not receive much attention. In this paper, we revisit the differential attack against several S-Box based block ciphers by carefully studying the differential characteristics. Inspired by Matsui's algorithm, we provide an improved solution with the aid of several searching strategies, which enable us to find by far the best differential characteristics for the two investigated ciphers (LBlock, TWINE) efficiently. Furthermore, we provide another way to evaluate the security of ciphers against differential attack by comparing the strength of the ciphers from differential characteristic's point of view, and we also investigate the accuracy when using the active S-Box to evaluate the security margin against differential attack, which is the common method adapted when new ciphers are designed.
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Je Sen Teh
CSCloud3
2015 A New Statistical Approach for Integral Attack
Jiageng Chen, Atsuko Miyaji, Chunhua Su, Liang Zhao 0020
NSS3
2015 An improved preimage attack against HAVAL-3
Jian Guo 0001, Chunhua Su, Wun-She Yap
Inf. Process. Lett.2
2014 Distributed Pseudo-Random Number Generation and Its Application to Cloud Database
Jiageng Chen, Atsuko Miyaji, Chunhua Su
ISPEC3
2014 Improving Impossible Differential Cryptanalysis with Concrete Investigation of Key Scheduling Algorithm and Its Application to LBlock
Jiageng Chen, Yuichi Futa, Atsuko Miyaji, Chunhua Su
NSS4
2014 A Provable Secure Batch Authentication Scheme for EPCGen2 Tags
Jiageng Chen, Atsuko Miyaji, Chunhua Su
ProvSec3
2014 Collaborative agglomerative document clustering with limited information disclosure
abstract
ABSTRACT Document clustering is a practical and powerful data mining technique to analyze large amount of documents and large sets of text or hypertext documents. However, it also brings the problem of sensitive information leaking in disregard of privacy, especially when it is executed in distributed environment. In this paper, we propose a cryptography‐based framework to realize privacy‐preserving document clustering among the users under the distributed environment; there are two parties, each having his private document database, want to collaboratively execute agglomerative document clustering without disclosing their private contents. We provide two implementations of such a framework, one is with more precision and stronger security but requires more computational resources. The other is a simplified version with less computational complexity and achieves higher processing speed. Additionally, we provide the security proofs and experimental analysis of precision and scalability of our proposal. Copyright © 2013 John Wiley & Sons, Ltd.
Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai
Secur. Commun. Networks1
2012 Analysis and Improvement of Privacy-Preserving Frequent Item Protocol for Accountable Computation Framework
abstract
Nowadays, data collection and processing becomes ubiquitous in social and business areas, especially in Internet of Things. However, sensitive information leakage is a critical issue. To solve problem, privacy-preserving techniques are strongly needed. Jiang {\em et al.} proposed a protocol of finding frequent item in accountable computing (AC) framework which enables two parties to conduct collaborative computation on their transactional databases to find out the common frequent items without disclosing their private data to the other party. Their scheme was proposed in a secure two-party computation model against malicious adversaries. In this paper, we analyze the implementation details of AC-framework and identify some security weaknesses in their scheme. Furthermore, we clarify the security requirements for the AC-framework and present an augmented solution to enhance security.
Chunhua Su, Guilin Wang, Kouichi Sakurai
TrustCom1
2010 Two robust remote user authentication protocols using smart cards
Kuo-Hui Yeh, Chunhua Su, Nai-Wei Lo, Yingjiu Li, Yi-Xiang Hung
J. Syst. Softw.2
2008 A New Scheme for Distributed Density Estimation based Privacy-Preserving Clustering
abstract
The sensitive information leakage and security risk is a problem from which both individual and enterprise suffer in massive data collection and the information retrieval by the distrusted parties. In this paper, we focus on the privacy issue of data clustering and point out some security risks in the existing data mining algorithms. Associated with cryptographic techniques, we initiate an application of random data perturbation (RDP) which has been widely used for preserving the privacy of individual records in statistical database for the distributed data clustering scheme. Our scheme applies linear transformation of Gaussian distribution perturbed data and general additional data perturbation (GADP) schemes to preserve the privacy for distributed kernel density estimation with the help of any trusted third party. We also show that our scheme is more secure against the random matrix-based filtering attack which is based on analysis of the distribution of the eigenvalues by using two RDP methods.
Chunhua Su, Feng Bao 0001, Jianying Zhou 0001, Tsuyoshi Takagi, Kouichi Sakurai
ARES1
2008 A Distributed Privacy-Preserving Association Rules Mining Scheme Using Frequent-Pattern Tree
Chunhua Su, Kouichi Sakurai
ADMA1
2007 Two-Party Privacy-Preserving Agglomerative Document Clustering
Chunhua Su, Jianying Zhou 0001, Feng Bao 0001, Tsuyoshi Takagi, Kouichi Sakurai
ISPEC1